← Vulnerability feed

Vulnerability record · CVE-2025-61591 · published 3 October 2025

CVE-2025-61591: Anysphere cursor os command injection vulnerability

Anysphere · Cursor

Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an attacker can impersonate a malicious MCP server and return crafted, maliciously injected commands during the interaction process, leading to command injection and potential remote code execution. If chained with an untrusted MCP service via OAuth, this command injection vulnerability could allow arbitrary code execution on the host by the agent. This can then be used to directly compromise the system by executing malicious commands with full user privileges. This issue does not currently have a fixed release version, but there is a patch, 2025.09.17-25b418f.

8.8 CVSS 3.1 High EPSS 1.2% · top 34.2% CWE-78 · OS command injection
8.8CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an attacker can impersonate a malicious MCP server and return crafted, maliciously injected commands during the interaction process, leading to command injection and potential remote code execution. If chained with an untrusted MCP service via OAuth, this command injection vulnerability could allow arbitrary code execution on the host by the agent. This can then be used to directly compromise the system by executing malicious commands with full user privileges. This issue does not currently have a fixed release version, but there is a patch, 2025.09.17-25b418f.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-61591 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.9CVE-2026-26268Anysphere cursor missing authorization vulnerabilityCursor is a code editor built for programming with AI. Sandbox escape via writing .git configuration was possible in versions prior to 2.5. A malicio…EPSS 0.42%9.8CVE-2025-59944Anysphere cursor vulnerabilityCursor is a code editor built for programming with AI. Versions 1.6.23 and below contain case-sensitive checks in the way Cursor IDE protects its sen…EPSS 0.41%9.8CVE-2025-54130Anysphere cursor improper authorization vulnerabilityCursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. If…EPSS 0.30%9.8CVE-2025-54135Anysphere cursor os command injection vulnerabilityCursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the…EPSS 1.8%9.3CVE-2026-50548Anysphere cursor path traversal vulnerabilityCursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox gra…EPSS 1.0%9.3CVE-2026-50549Anysphere cursor link following vulnerabilityCursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the…EPSS 1.0%8.8CVE-2025-64106Anysphere cursor os command injection vulnerabilityCursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor's MCP server installation ena…EPSS 0.37%8.8CVE-2025-64107Anysphere cursor path traversal vulnerabilityCursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may lead to RCE. Cursor detects p…EPSS 0.36%

Source: NIST National Vulnerability Database (record CVE-2025-61591), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.